Sooner or later, every company with a technology roadmap has the same argument in the same meeting room. Do we buy something that already works, or do we build something that is ours? The CTO wants control, the CFO wants a predictable number, and whoever is responsible for legal usually walks in at the end and is asked to “just check the contract”.
That is the wrong moment. Whether you license an off-the-shelf platform, subscribe to a SaaS product or commission bespoke code from a development house, the choice decides three things that are expensive to undo later: what you actually own, where your data goes, and how easily you can leave.
This guide is written for the people in that room in Romania — CTOs, general counsel, procurement leads and founders. It deals with private commercial projects only; public procurement has its own rules and is not covered here.
Who this guide is for: CTOs, general counsel, procurement leads, founders and in-house counsel in Romania deciding whether to license a product (including SaaS) or commission custom software.
What you will get: a practical legal decision framework, a contract drafting checklist, an overview of regulatory risks and mitigations, and model clause prompts for counsel to adapt with local advice.
There is rarely one right answer to the buy-or-build question. It depends on how fast you need the thing, how close it sits to what makes your business different, whether you need to own the code, and how sensitive the data running through it will be. What follows turns those commercial instincts into legal questions you can actually answer.
Read it as a working checklist rather than front to back. Start with the decision framework, then go to the parts that match your project: IP ownership if you are building, licensing and exit if you are buying, data protection if personal data is anywhere near it (it usually is). Statutory references point to the text in force, and every sample clause is a starting point for discussion, not a finished draft. None of this is legal advice — have local counsel look at your contract before you sign it.
Before anyone drafts anything, put the project through a filter. The commercial side — cost, speed, control — and the legal side — ownership, regulation, exposure — have to be looked at together. A team that chooses a product because it can be live in six weeks has made a legal decision too, whether or not anyone noticed: it has accepted whatever rights that licence gives, and nothing more.
Some facts should tip the scales on their own. When any of these is present, the legal analysis stops being a footnote and starts driving the decision.
A simple way to run this is as a sequence of questions: Is time critical? Do we need to own the IP? Is personal data involved, and where will it sit? Can we get out cleanly if we need to? The answers usually point to the right vehicle — licence, subscription or commissioned build — and, just as usefully, to the clauses you cannot give up.
Strip away the commercial language and the difference is simple. When you buy, you acquire a right to use. When you build, you commission a work. That distinction decides what you own, what you are allowed to do with it, and what is left in your hands when the relationship ends.
A licence gives you exactly what its text says, and not a line more. The grant and its restrictions are the whole deal. The common shapes are:
The protection of computer programs is harmonised across the EU by Directive 2009/24/EC, which Romania implements through Law No. 8/1996 on copyright and related rights. One Romanian detail is worth knowing before you read any licence: where a software use contract is silent, art. 76 of the law presumes that the user receives a non-exclusive right of use that it cannot pass on to others. If you need more — affiliates, contractors, a future buyer of your business — the licence has to say so.
For perpetual licences there is also the question of resale. In UsedSoft v Oracle (Case C-128/11), the Court of Justice held that the distribution right in a copy of a program is exhausted where the rightholder authorises its download and grants a right to use it for an unlimited period in return for a fee corresponding to the economic value of the copy. In practice that opened a market for second-hand licences. The Court has kept that reasoning tied to software: in Tom Kabinet (Case C-263/18) it declined to extend it to e-books. And it offers nothing to a SaaS customer, who never receives a copy in the first place.
When you commission software, what you are paying for is a work: source code, object code, documentation and everything around them. Here is the point that surprises clients most often. Paying for that work does not, by itself, make it yours. Under Romanian law the economic rights start with the author, and the commissioning party acquires them only if the contract transfers them — in the form the statute requires. This is the single most important legal difference between buying and building, and it is exactly where weak contracts let their clients down.
If you are building, IP ownership is the centre of gravity. Get it wrong and you can pay in full for software you do not own, cannot sell and cannot freely change. The rules are Romanian, set against an EU background.
Copyright in computer programs is governed by Law No. 8/1996, republished in the Official Gazette No. 489 of 14 June 2018. The republication renumbered the articles, and a surprising number of commentaries still cite the old numbers, so check any reference you are given. Computer programs are protected as works under art. 7, and the specific rules for software sit in Chapter IX (art. 73–82).
Protection arises the moment the code is written. There is nothing to register for a bespoke build: the software register kept by the Romanian Copyright Office (ORDA) under art. 17 of Government Ordinance No. 25/2006 concerns programs sold through retail channels, not a system built for one client. Copyright protects the expression of the program — the code — not the ideas, procedures or algorithms behind it.
Because economic rights begin with the author, a company commissioning software has to acquire them by contract. There is one important exception: under art. 75, economic rights in programs written by employees in the exercise of their duties, or on the employer’s instructions, belong to the employer unless the contract says otherwise. That rule does not reach a freelancer working through a PFA, or an outsourcing agency, or an employee whose duties never covered software. For all of them, nothing passes unless it is assigned.
Romanian law frames the transfer as an assignment (cesiune) of economic rights, which can be exclusive or non-exclusive. In practice the choice looks like this:
A short sample assignment clause, for discussion only, might read: “The Developer assigns to the Customer the economic rights in the Deliverables listed in Schedule [X], namely the rights of reproduction, distribution, adaptation, translation and communication to the public, for the modes of use set out in Schedule [X], worldwide, for the entire term of protection, including all source code, object code and documentation, in consideration of [RON …] of the Fees, which the parties allocate to this assignment.” Notice what is in it: named rights, modes of use, territory, duration and a remuneration figure. Local counsel should still adapt it to the deal.
Then look at the flow-down, because that is where the chain of title usually breaks. Art. 42(2) makes an assignment of all of an author’s future works absolutely void. Yet the standard master agreement asks every developer to sign exactly that on day one. The workable version assigns per project and per deliverable, with an undertaking to sign confirmatory assignments as the work is produced.
Beyond the economic rights, the author keeps moral rights — attribution, integrity of the work and others listed in art. 10. Art. 11(1) is blunt: moral rights cannot be waived or transferred. The software chapter contains no exception to that.
So a contract cannot make moral rights disappear. What it can do is secure practical undertakings about how they are exercised — for example, that individual developers need not be named in the product, and that ordinary maintenance and modification will not be treated as an attack on the integrity of the work. Be realistic about such a covenant: the statute does not guarantee that a court will enforce it, so draft the rest of the contract so that it still holds if the covenant does not.
Once you decide to build, the contract becomes your main risk-management tool. It allocates ownership, holds scope in place, defines what “done” means and tells you what happens when it is not. These are the clauses no serious commissioned build should go without.
Acceptance testing is the strongest lever a customer has, because it ties money to proof. Define the deliverables precisely, attach the specification and agree objective acceptance criteria. A workable acceptance regime covers:
Tie the final milestone to successful acceptance and the developer stays motivated right up to delivery. And if real or realistic data is used in testing, remember that the developer is processing personal data on your behalf — which means the data processing agreement has to be in place for the test phase, not chased afterwards.
Pay against accepted deliverables, not against the calendar. Custom projects almost always change shape along the way, so change control needs discipline: every change described, priced and approved in writing before work starts. A fixed-price envelope for defined scope, or a cap on change orders, helps keep the budget honest.
The core warranties are conformity with the specification, non-infringement of third-party IP and, where it fits, fitness for a stated purpose. The IP indemnity matters most: the developer should defend infringement claims and bear the cost of them.
On liability caps, two Romanian rules shape what will actually survive. Art. 1355 of the Civil Code prevents a party from limiting liability for material damage caused intentionally or through gross negligence. And art. 1203 provides that certain clauses in standard terms — limitation of liability among them — take effect only if the other party expressly accepts them in writing. Set the cap so that it does not leave you carrying the full cost of an infringement or a data breach.
Owning custom software means owning its upkeep. The maintenance contract should define support windows, response and resolution times, update and security-patch obligations, and what happens when service levels are missed. Two points are often forgotten. First, make sure maintenance survives delivery and can be moved to another provider, which is why source-code access matters. Second, updates are no longer purely a commercial matter. The Cyber Resilience Act’s reporting obligations for actively exploited vulnerabilities and severe incidents have applied since 11 September 2026, and the new Product Liability Directive, due for transposition by 9 December 2026, treats software as a product — a missing security update can make it defective. The contract should say who is the manufacturer, who keeps the software bill of materials, and how long security updates will run.
On the buy side, the long-term risk is lock-in: becoming so dependent on a vendor’s platform, formats or hosting that leaving is theoretically possible and practically out of the question. Odysseus had himself tied to the mast before he heard the sirens. Exit terms work the same way — they have to be agreed while you still have the will, and the leverage, to insist on them.
Read the grant closely. Who may use the software, for what purposes, and can you extend it to affiliates or contractors? Remember that a silent licence is presumed non-exclusive and non-transferable. For bespoke or business-critical systems, negotiate source-code escrow: the vendor deposits the code with an independent agent, to be released on defined events such as insolvency or an unremedied breach. Insist on verification that the deposited code actually builds, or you may inherit an archive nobody can compile. Test the insolvency trigger in particular — whether a release keyed to the vendor’s insolvency survives the judicial administrator’s powers under Law No. 85/2014 is an open question worth discussing with counsel before you rely on it. Where escrow is not available, open standards or shared IP arrangements can do part of the work.
Every SaaS or licence agreement needs an exit plan. That means transition assistance, guaranteed export of your data in a usable, non-proprietary format, and reasonable cooperation in moving to the next provider.
For cloud and SaaS services, EU law now does some of this for you. The Data Act has applied since 12 September 2025, and for data processing services it caps the notice period for starting a switch at two months, sets a maximum transitional period of 30 calendar days, and requires at least 30 days afterwards to retrieve your data. Reduced switching charges are allowed only until 12 January 2027; after that date, providers may not charge for switching at all. The rules on switching charges, and some of the interoperability duties, do not apply to a service built mostly around a single customer’s needs and not offered at broad commercial scale, so check how your contract describes the service. Data portability is a commercial protection and, for personal data, a regulatory one too.
Watch for automatic renewals, uncapped price increases and notice periods short enough to miss. Negotiate a renewal window you can actually act on, a cap on price rises and clear termination rights. Romanian law helps here too: under art. 1203 of the Civil Code, a tacit renewal clause buried in a vendor’s standard terms takes effect only if you expressly accepted it in writing. That is a useful argument; it is no substitute for a diary reminder.
Any software that processes personal data brings GDPR with it, supervised in Romania by the National Supervisory Authority for Personal Data Processing (ANSPDCP). Buying or building changes how those obligations are shared out.
With SaaS, the vendor usually acts as your processor — or, for some of its own purposes, as a separate controller. With custom software you host yourself, you generally remain the controller and carry full responsibility for the environment. Settle the roles at the start, because they decide who owes what, and to whom.
Where a vendor or developer processes personal data on your behalf, a data processing agreement meeting art. 28 GDPR is mandatory. It should bind the processor to your instructions, impose confidentiality and security obligations, list authorised sub-processors and give you audit and assistance rights.
If data goes outside the EEA to a country without an adequacy decision, you need appropriate safeguards — typically the Commission’s Standard Contractual Clauses — together with a transfer risk assessment. For US providers, check whether the recipient is certified under the EU-US Data Privacy Framework. Whichever route you take, build security in from the start and align your technical and organisational measures with GDPR and ANSPDCP guidance.
Building in-house may qualify for Romanian research-and-development tax incentives, available under specific conditions. Eligibility usually turns on how the activity is classified and on keeping proper documentation from the start. These incentives can change the economics of a build meaningfully, but the rules are detailed and have been amended repeatedly in recent years. Treat this as a flag, not a figure: confirm current eligibility with a tax adviser and the official guidance before it goes into your business case.
The table below sets the main legal and commercial factors side by side, with the contractual protections that answer each risk.
| Topic | Buy / Licence | Build / Commission | Recommended contractual protections |
|---|---|---|---|
| IP ownership | Licensor keeps copyright; you get use rights, non-exclusive unless stated | You can own the code, but only through an assignment meeting art. 42(1) | Clear licence scope; assignment naming rights, modes of use, duration, scope and remuneration; per-deliverable flow-down; moral rights non-exercise covenant |
| Cost certainty | Predictable fees, but total cost of ownership moves | Higher upfront cost; change requests unpredictable | Fixed-price milestones; cap on change orders; SLA service credits |
| Time to market | Faster | Slower | Transitional services; phased delivery |
| Vendor lock-in | Dependence on the vendor | Lower if you own the code, but you carry maintenance | Escrow with verification; exit assistance; data export; Data Act switching rights |
| Data protection | SaaS often involves processing outside the EU | Data can stay local or in a cloud you choose | Art. 28 DPA (including for testing); sub-processor list; SCCs or adequacy |
| Maintenance & updates | Vendor-managed; vendor controls roadmap | You control the roadmap; you need a maintenance contract | Maintenance SLA; security-update period; CRA and product-liability allocation |
Whichever way the analysis points, disciplined execution is what protects the result. Before you sign:
Take a hypothetical Bucharest fintech that needs a lending-decision engine built around its own risk model. An off-the-shelf platform would be live in weeks. But the company would not own the logic that sets it apart, and sensitive personal and financial data would sit on a vendor’s infrastructure abroad.
So it builds. The development contract assigns the economic rights in the engine — source code and documentation included — naming the rights, the modes of use, the duration, the territory and the part of the fee paid for the assignment. The developer warrants that it can assign, gives an IP infringement indemnity, and undertakes to obtain per-deliverable assignments from each of its own developers rather than a blanket assignment of future works. Acceptance runs module by module against objective criteria, and the final payment is released only when the whole system passes.
Because the fintech will host the data and remain controller, it signs an art. 28 DPA with the developer for any processing during development and testing, and aligns its security measures with GDPR and ANSPDCP guidance. A maintenance SLA with defined response times, a security-update commitment and the source code held in-house keep the system alive if the relationship ends.
Two regulatory questions sit alongside the contract. If the company is a financial entity within the scope of DORA, the mandatory contractual terms for ICT services in art. 30 have applied since 17 January 2025. And if the engine evaluates the creditworthiness of individuals, it is a high-risk AI system under the AI Act; following the Digital Omnibus on AI (Regulation (EU) 2026/1744), those high-risk obligations apply from 2 December 2027. Building the documentation now is far cheaper than reconstructing it later.
The outcome: the fintech owns what makes it different, controls its data and remains free to take the product wherever it wants.
Buy or build is as much a legal question as a technical one. Buying gives you speed and predictability, but ownership and control stay with the vendor. Building gives you ownership and your own roadmap, but only if the contract gets the assignment, acceptance, warranties and maintenance right. Either way, IP, data protection and exit rights decide your exposure for years to come.
The details that make or break those protections — the elements of a valid assignment, the treatment of future works, the limits on moral-rights covenants, escrow triggers and data transfers — turn on precise drafting under Romanian and EU law. Bring in qualified local counsel before you commit, not after the first dispute. This guide is for general information only and does not constitute legal advice.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Razvan Alexandru Olaru at Olawru, a member of the Global Law Experts network.
posted 18 minutes ago
posted 37 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message